Issue with ADFS - DUO+VMware vSphere

ZalanCL 6 Reputation points
2022-10-17T12:27:53.18+00:00

Hi there!

I’ve recently started a new DUO account to trial a setup with DUO, Microsoft ADFS and VMware vSphere.

Currently the base setup (ADFS+vSphere) is deployed and working alright, meaning that vSphere is able to authenticate through ADFS. But as soon as I introduce DUO in the equation, I get the following error in ADFS:

• Error details: MSIS7065: There are no registered protocol handlers on path /adfs/oauth2/authorize/ to process the incoming request.

The setup has the following versions:

vSphere 7.0.3.00700
Windows Server 2019 with ADFS
DUO duo-adfs3-2.0.0

To be clear, I do receive the pop-up in my device from DUO when attempting to login, and the redirect to DUO (api-XXXXXXXX.duosecurity.com in my case) is working, the issue seems to be when returning to ADFS, I get the above error.

It’s not clear to me where (in what component) the error is.

I’ve seen a blog post from VMware stating that this setup works (https://blogs.vmware.com/customer-experience-and-success/2022/06/tam-lab-enabling-mfa-in-vsphere-7.html) but it is from June 2022, when frameless DUO still wasn’t implemented.

The implementation also follows the blog post above, or rather, the videos from it.

Would anyone be able to further provide troubleshooting steps for this issue?

Kind regards.

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,209 questions
0 comments No comments
{count} vote

1 answer

Sort by: Most helpful
  1. Genessy 0 Reputation points
    2023-07-13T13:47:35.7433333+00:00

    I know this response is a bit late. We had this all implemented and functioning well, and then we needed to upgrade Duo for ADFS in order to support the universal prompt. It turns out that the newer version of Duo no longer supports OIDC connections. I believe the only solution is to downgrade the version of Duo for ADFS.

    User's image

    0 comments No comments